Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-3565
Description:Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2013.0241  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-3565
http://git.videolan.org/gitweb.cgi/vlc.git/?p=vlc.git;a=commitdiff;h=bf02b8dd211d5a52aa301a9a2ff4e73ed8195881
http://lists.opensuse.org/opensuse-updates/2014-03/msg00001.html
http://www.videolan.org/developers/vlc-branch/NEWS
https://www3.trustwave.com/spiderlabs/advisories/TWSL2013-007.txt




© 1998-2025 E-Soft Inc. All rights reserved.